One Year Without Security Issues in MS SQL Server 2005

The security guys at Microsoft are posting about how MS SQL 2005 didn’t had any security vulnerabilities at all (you can check Secunia to confirm it). The secret? Apparently, like in other products (no, IE is not part of those products, its core is 5 years old after all), the real difference has been in that they’ve applied the “Security Development Lifecycle“.

Reviewing the CVE list, there have been zero SQL Server disclosures since September 2004 and that is the only one in the past 3 years